Description
Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash
values without properly restricting the ability to trigger hash collisions
predictably, which allows context-dependent attackers to cause a denial of
service (CPU consumption) via crafted input to an application that
maintains a hash table, as demonstrated by a universal multicollision
attack against the MurmurHash3 algorithm, a different vulnerability than
CVE-2012-2739.
Notes
jdstrand> no 2.3 update as of 2013/12/20. 2.4/armhf needs to be fixed
jdstrand> the MurmurHash3 was introduced in OpenJDK 7 7u9-2.3.3 and OpenJDK 6
6b24-1.11.5 as part of the fix for CVE-2012-2739.
jdstrand> icedtea-web not affected (code not present)
jdstrand> patches/security/20121016/7158800.patch introduced this (ie
murmur3_32())
jdstrand> per comment #1 in https://bugzilla.redhat.com/show_bug.cgi?id=880705
SipHash-2-4 is not vulnerable
sbeattie> purported to be fixed in 7u40
Package
Upstream: | needed
|
Ubuntu 12.04 ESM (Precise Pangolin): | DNE
(precise was needed)
|
Ubuntu 14.04 LTS (Trusty Tahr): | needed
|
Ubuntu 16.04 LTS (Xenial Xerus): | DNE
|
Ubuntu 18.04 LTS (Bionic Beaver): | DNE
|
Ubuntu 18.10 (Cosmic Cuttlefish): | DNE
|
Ubuntu 19.04 (Disco Dingo): | DNE
|
Package
Upstream: | ignored
(eol in lucid, oneiric)
|
Ubuntu 12.04 ESM (Precise Pangolin): | DNE
|
Ubuntu 14.04 LTS (Trusty Tahr): | DNE
|
Ubuntu 16.04 LTS (Xenial Xerus): | DNE
|
Ubuntu 18.04 LTS (Bionic Beaver): | DNE
|
Ubuntu 18.10 (Cosmic Cuttlefish): | DNE
|
Ubuntu 19.04 (Disco Dingo): | DNE
|
Package
Upstream: | needed
|
Ubuntu 12.04 ESM (Precise Pangolin): | DNE
(precise was released [7u51-2.4.4-0ubuntu0.12.04.2])
|
Ubuntu 14.04 LTS (Trusty Tahr): | not-affected
(7u51-2.4.6-1ubuntu4)
|
Ubuntu 16.04 LTS (Xenial Xerus): | DNE
|
Ubuntu 18.04 LTS (Bionic Beaver): | DNE
|
Ubuntu 18.10 (Cosmic Cuttlefish): | DNE
|
Ubuntu 19.04 (Disco Dingo): | DNE
|
Patches:
Package
Upstream: | ignored
(end of life)
|
Ubuntu 12.04 ESM (Precise Pangolin): | DNE
|
Ubuntu 14.04 LTS (Trusty Tahr): | DNE
|
Ubuntu 16.04 LTS (Xenial Xerus): | DNE
|
Ubuntu 18.04 LTS (Bionic Beaver): | DNE
|
Ubuntu 18.10 (Cosmic Cuttlefish): | DNE
|
Ubuntu 19.04 (Disco Dingo): | DNE
|
Package
Upstream: | ignored
(upstream not redistributable)
|
Ubuntu 12.04 ESM (Precise Pangolin): | DNE
|
Ubuntu 14.04 LTS (Trusty Tahr): | DNE
|
Ubuntu 16.04 LTS (Xenial Xerus): | DNE
|
Ubuntu 18.04 LTS (Bionic Beaver): | DNE
|
Ubuntu 18.10 (Cosmic Cuttlefish): | DNE
|
Ubuntu 19.04 (Disco Dingo): | DNE
|
Updated: 2019-01-14 21:14:42 UTC (commit 51f9b73af244ba86b9321e46e526586c25a8e060)